Showing 1 vulnerability on this page for Password Policy Manager | Password Manager

Signals CISA KEV Ransomware Nuclei
cyberlord92 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Password Policy Manager | Password Manager <= 2.0.5 - Missing Authorization to Authenticated (Subscriber+) Configuration Log Out

The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'moppm_ajax' AJAX endpoint in all versions up to, and including, 2.0.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to log out the site's connection to miniorange.

CWE-862Oct 25, 2025
CVSS4.3v3.1EPSS0.188%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX